Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share
  • icon

Nullsoft Fixes Critical Winamp Bug


Nullsoft has fixed a critical flaw in the way its flagship Winamp music player processed playlists that could have allowed attackers to grab control of PCs.



Nullsoft late Monday fixed a critical flaw in its flagship Winamp music player that could have allowed attackers to grab control of PCs simply by duping people into downloading a playlist.

The fix, dubbed Winamp 5.13, can be downloaded from the Nullsoft Web site.

Alternately, users can download only the affected DLL -- "in_mp3.dll" -- from here, and place it in the Winamp\Plugins folder.

Various security firms raised alerts on Monday to warn Winamp users, with one -- Danish company Secunia -- tagging it with its highest threat level, "Extremely critical."

A moderator on a Nullsoft message board said Monday that the patched DLL would be included in the next public releases of Winamp 5.2 beta, "hopefully today." The most recent build of the beta on the Nullsoft site, marked "365," was posted prior to the vulnerability's discovery, however.


Subscribe to RSS


Advertisement


CAREER CENTER
Ready to take that job and shove it?



TechCareers

SEARCH
Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.





Subscription Info
Apply for a free 52-week subscription to InformationWeek (a $199 value)

Last Name:

First Name:

Title:

Company Name:

City:

Business Address:

Zip:

State:

Email Address:

NOTE: Offer valid for U.S., U.S. possessions, & Canada only

            

Join economist Chris Cornell and 3 CIOs in an Exclusive Online Exchange for Senior IT Executives: Using IT to Drive Value in a Turbulent Economy. November 5th only.